Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
CVE-2023-27522

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
7 March 2023

Summary

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.

Special characters in the origin response header can truncate/split the response forwarded to the client.

Affected Version(s)

Apache HTTP Server 2.4.30 <= 2.4.55

References

EPSS Score

1% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Dimas Fariski Setyawan Putra (nyxsorcerer)
.